OWASP API Top 10 #2 - Broken Authentication Explained (With Live Demo)

Опубликовано: 23 Март 2026
на канале: APIsec University
473
12

In this APIsecU live session, Christine Bevilacqua and Theresa Pereira dive deep into OWASP API Security Risk #2: Broken Authentication - exploring how weak or missing authentication exposes APIs to account takeovers, data theft, and large-scale breaches.
Learn how attackers exploit authentication flaws, see a live pentesting demo on CRAPI, and understand how to implement defenses beyond just relying on your gateway or WAF.

Featuring:
Real-world case study: T-Mobile breach (37M records)
Common pitfalls: weak tokens, poor session hygiene, missing auth
Live demo: discovering and exploiting broken authentication in CRAPI
Tools covered: Postman, BurpSuite, APIsec Scan
Preventive controls and layered defenses

Key Learnings:
Understand how Broken Authentication enables unauthorized access and impersonation.
Learn how attackers identify and exploit weak endpoints.
Discover tools and methods for API auth testing.
Recognize why gateways and WAFs aren’t enough.
Learn how to harden APIs with deny-by-default, rate limiting, and token valid

https://www.apisecuniversity.com/discord - Connect with us on Discord to discuss OWASP, bug bounty, API security, and more. Explore opportunities through the APIsec Ambassador Program, monthly scholarships, and exclusive tools like App Bolt for live traffic inspection and API analysis.

#apisecurity #OWASPAPI #BrokenAuthentication #PenTesting #CyberSecurity #APISecurityTesting #OWASPTop10 #APISecU #BurpSuite #Postman #JWT #Authentication #Authorization #TMobileBreach #CRAPI